How we collect, use, store, and protect your personal information. We are committed to safeguarding your privacy in full compliance with Philippine law.
For the purposes of the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, the personal information controller responsible for your data is:
Morph Tech Inc. is committed to protecting and respecting your privacy. This Privacy Policy describes our practices regarding the personal data we collect through the StressAId platform in compliance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations (IRR), and all relevant issuances of the National Privacy Commission (NPC).
We collect the following categories of personal information, each for a specific and legitimate purpose:
We process your personal data under the following lawful bases as defined by Section 12 and Section 13 of RA 10173:
| Data Category | Legal Basis | Purpose |
|---|---|---|
| Account info | Contractual necessity | To create and manage your account |
| Wellness data | Explicit consent | To provide personalized wellness tracking |
| Payment data | Contractual necessity | To process subscriptions and verify access |
| Usage analytics | Legitimate interest | To improve the platform and fix issues |
| Org aggregate reports | Legitimate interest + consent | To provide anonymized wellness trends to organizations |
| AI conversations | Explicit consent | To deliver AI wellness guidance and improve quality |
You may withdraw your consent at any time by contacting our Data Protection Officer at dpo@stressaidph.com. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal.
We use your personal data for the following purposes, and no others:
We do not sell, rent, lease, or trade your personal data to any third party. Period.
Your data may be processed by the following third-party service providers acting as personal information processors under our instruction, pursuant to data processing agreements that require them to protect your data to standards no less than those described in this policy:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (Singapore/US) | Database, authentication, file storage | All account and wellness data (encrypted at rest) |
| Google (US) | OAuth authentication | Authentication tokens only; we receive name, email, photo |
| PayMongo (Philippines) | Payment processing | User email, subscription type, amount — they handle card data |
| Anthropic (US) | AI conversation processing (Claude) | AI chat messages (processed server-side, not stored by Anthropic beyond ephemeral processing) |
| OpenAI (US) | Video transcription & embedding | Video audio for transcription; text for embeddings (Coach Ricky content only, no user data) |
| Bunny.net (EU) | Video streaming CDN | Coach Ricky's video files (no personal user data) |
| Resend (US) | Transactional email delivery | Email address and email content (receipts, alerts) |
| Vercel (US) | Website hosting & CDN | Static files only; no personal data processed |
Other disclosures. We may disclose your personal data if required to do so by law, regulation, legal process, or governmental request under Philippine law, including valid subpoenas, court orders, or lawful requests from Philippine regulatory agencies such as the National Privacy Commission (NPC).
We implement organizational, physical, and technical security measures to protect your personal data against unauthorized access, accidental loss, alteration, or destruction, in accordance with Section 20 of RA 10173:
StressAId uses browser localStorage (not cookies) for the following essential functions:
We do not use:
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by applicable law:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account info | Duration of account + 30 days after deletion request | Service delivery + processing deletion |
| Wellness data | Duration of account | Continuous wellness tracking |
| AI conversations | Duration of account (user can delete individual sessions) | Conversation continuity and user reference |
| Payment records | 5 years after transaction | BIR tax compliance requirements |
| Analytics events | 12 months | Platform improvement |
| Security logs | 12 months | Security monitoring and incident response |
Upon account deletion or expiry of the retention period, we will securely delete or anonymize your personal data within thirty (30) days, except where retention is required by Philippine law (e.g., BIR record-keeping requirements under the National Internal Revenue Code).
As a data subject under the Philippine Data Privacy Act, you have the following rights. We will respond to all legitimate requests within fifteen (15) days of verification of your identity:
To exercise any of these rights, contact our Data Protection Officer:
When your account is linked to an organization through StressAId:
When you use the AI Wellness Companion, your messages are processed as follows:
Some of our third-party service providers process data outside the Philippines. In accordance with Section 21 of RA 10173 and NPC Circular 2022-01 on cross-border data transfers:
All cross-border transfers are subject to appropriate safeguards, including data processing agreements that require the receiving party to protect your data with security measures at least equivalent to those required under RA 10173. These transfers are necessary for the performance of our contract with you (providing the StressAId service) as permitted under Section 21(a) of the Act.
PayMongo, our payment processor, processes all payment data within the Philippines.
StressAId is designed for users aged eighteen (18) and above. We do not knowingly collect personal data from children under thirteen (13).
Parents or guardians who believe their child's data has been collected without consent may contact us at privacy@stressaidph.com.
In the event of a personal data breach that is likely to cause serious harm to affected data subjects, we will:
Notification to data subjects will include: the nature of the breach, the personal data potentially involved, measures taken to address the breach, and recommended actions you can take to protect yourself.
We may update this Privacy Policy from time to time. When we make material changes:
Your continued use of StressAId after the effective date of a revised policy constitutes your acceptance of the changes, except where fresh consent is required for sensitive personal information.
For any questions, requests, or complaints regarding this Privacy Policy or our data practices: